<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic How to make Splunk ES override urgency changes? in Splunk Enterprise Security</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/How-to-make-Splunk-ES-override-urgency-changes/m-p/617109#M11118</link>
    <description>&lt;P&gt;Hi all,&lt;/P&gt;
&lt;P&gt;I have a correlation search that passes alerts from another system into ES and I need to prevent the urgency of the alert from being changed by ES.&lt;/P&gt;
&lt;P&gt;Essentially I (think I) need ES to ignore the priority of any asset or identity associated with the incident so that the urgency doesn't change.&lt;/P&gt;
&lt;P&gt;Cany anyone offer any advice on how to do this?&lt;/P&gt;
&lt;P&gt;Thanks very much&amp;nbsp; &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;Edit: I should add, I didn't create the original correlation search and I don't have much experience in this area, hence the question. Thanks again!&lt;/P&gt;</description>
    <pubDate>Fri, 14 Oct 2022 14:52:27 GMT</pubDate>
    <dc:creator>Dworsnop</dc:creator>
    <dc:date>2022-10-14T14:52:27Z</dc:date>
    <item>
      <title>How to make Splunk ES override urgency changes?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/How-to-make-Splunk-ES-override-urgency-changes/m-p/617109#M11118</link>
      <description>&lt;P&gt;Hi all,&lt;/P&gt;
&lt;P&gt;I have a correlation search that passes alerts from another system into ES and I need to prevent the urgency of the alert from being changed by ES.&lt;/P&gt;
&lt;P&gt;Essentially I (think I) need ES to ignore the priority of any asset or identity associated with the incident so that the urgency doesn't change.&lt;/P&gt;
&lt;P&gt;Cany anyone offer any advice on how to do this?&lt;/P&gt;
&lt;P&gt;Thanks very much&amp;nbsp; &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;Edit: I should add, I didn't create the original correlation search and I don't have much experience in this area, hence the question. Thanks again!&lt;/P&gt;</description>
      <pubDate>Fri, 14 Oct 2022 14:52:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/How-to-make-Splunk-ES-override-urgency-changes/m-p/617109#M11118</guid>
      <dc:creator>Dworsnop</dc:creator>
      <dc:date>2022-10-14T14:52:27Z</dc:date>
    </item>
    <item>
      <title>Re: How to make Splunk ES override urgency changes?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/How-to-make-Splunk-ES-override-urgency-changes/m-p/617224#M11129</link>
      <description>&lt;P&gt;This is covered in the ES docs.&amp;nbsp;&lt;A href="https://docs.splunk.com/Documentation/ES/7.0.2/User/Howurgencyisassigned" target="_blank"&gt;https://docs.splunk.com/Documentation/ES/7.0.2/User/Howurgencyisassigned&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 15 Oct 2022 00:36:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/How-to-make-Splunk-ES-override-urgency-changes/m-p/617224#M11129</guid>
      <dc:creator>starcher</dc:creator>
      <dc:date>2022-10-15T00:36:45Z</dc:date>
    </item>
    <item>
      <title>Re: How to make Splunk ES override urgency changes?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/How-to-make-Splunk-ES-override-urgency-changes/m-p/617303#M11132</link>
      <description>&lt;P&gt;Thanks for the signposting&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/67425"&gt;@starcher&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Presumably I'm on the right lines here... "&lt;SPAN&gt;Severity defined in the search syntax results in an event where severity takes precedence over the severity defined in the notable event adaptive response action.&lt;/SPAN&gt;"&lt;/P&gt;&lt;P&gt;Therefore all I need to do is add " | eval severity="high" " to the end of my correlation search?&lt;/P&gt;</description>
      <pubDate>Mon, 17 Oct 2022 07:10:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/How-to-make-Splunk-ES-override-urgency-changes/m-p/617303#M11132</guid>
      <dc:creator>Dworsnop</dc:creator>
      <dc:date>2022-10-17T07:10:07Z</dc:date>
    </item>
    <item>
      <title>Re: How to make Splunk ES override urgency changes?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/How-to-make-Splunk-ES-override-urgency-changes/m-p/617466#M11134</link>
      <description>&lt;P&gt;That is correct.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 18 Oct 2022 01:52:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/How-to-make-Splunk-ES-override-urgency-changes/m-p/617466#M11134</guid>
      <dc:creator>starcher</dc:creator>
      <dc:date>2022-10-18T01:52:35Z</dc:date>
    </item>
  </channel>
</rss>

